Synopsys denied a data breach after a ransomware group claimed to have stolen Bosch intellectual property by exploiting the semiconductor design firm’s systems. The company stated it found no evidence of unauthorized access to its network or customer data following the cybercriminal group’s public allegations.
A ransomware group identifying itself as D1R listed both Synopsys and Bosch on its Tor-based leak website, asserting it had compromised Synopsys’ corporate client database. According to D1R, the group exploited a vulnerability in Synopsys’ website to access a database containing 40,000 client entries. The hackers threatened to publicly release the stolen data unless a ransom was paid and further claimed they used information obtained from Synopsys to breach systems at Bosch, a German engineering and technology giant.
D1R alleged it had obtained valuable intellectual property belonging to Bosch, including details about the company’s Controller Area Network (CAN) module implementation. The group reportedly demanded a $10,000 ransom from Bosch to prevent the leak of this data. However, a screenshot posted by the hackers as proof of their access to Bosch materials appears to show a document that is already publicly available—a user manual previously published online.
Synopsys, a silicon-to-systems design firm that specializes in electronic design automation software and pre-designed semiconductor blueprints, firmly rejected the claims. “We are continuously monitoring our network and have found no evidence of Synopsys or customer technical data being subject to unauthorized access,” the company said. It added, “We have not been contacted by this threat actor and, based on our investigation, claims of unauthorized access to customer confidential data are unfounded.” Synopsys also emphasized that “the security of data and systems is a priority for Synopsys.”
Bosch declined to answer specific questions about the incident but issued a broad statement on its cybersecurity posture. “Bosch places great importance on cybersecurity,” the company said. It noted that “as a globally networked industrial company, Bosch continuously strengthens the protection of its digital systems and expands its capabilities to respond quickly and in a coordinated manner to potential cyber incidents.” Bosch added that its strategy aims to “protect critical systems based on risk and limit the impact of potential attacks,” asserting that “cybersecurity makes a contribution to Bosch’s reliability, operational capability, and resilience.”
The allegations come heightened scrutiny of supply chain cybersecurity, particularly in the semiconductor and automotive sectors where intellectual property theft can have far-reaching consequences. Synopsys serves as a critical vendor to numerous technology and automotive firms, and any confirmed breach could undermine trust in its secure design ecosystem. Bosch, a major automotive supplier, relies on such vendors for embedded systems development, making third-party risk a central concern.
Although Synopsys and Bosch both maintain that no breach occurred or was substantiated, the incident illustrates how ransomware groups increasingly leverage unverified claims—and occasionally publicly available materials—to pressure companies into paying ransoms. The $10,000 demand is relatively low for a multinational corporation, suggesting the attackers may have lacked access to truly sensitive data or were testing their leverage. Regardless, the episode underscores the ongoing challenges companies face in defending against sophisticated cyber threats that target interconnected business ecosystems.
forum Comments (0)
No comments yet. Be the first to comment.